CVE-2026-0413
published 2026-06-09CVE-2026-0413: A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local…
PriorityP423medium4.3CVSS 4.0
AVAACLATNPRHUINVCNVIHVANSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.32%
24.2th percentile
A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netgear | rbe370 | < V12.1.2.1 | V12.1.2.1 |
| netgear | rbe770 | < V10.5.20.10 | V10.5.20.10 |
| netgear | rbr750 | < V7.2.8.5 | V7.2.8.5 |
| netgear | rbr840 | < V7.2.8.5 | V7.2.8.5 |
| netgear | rbr850 | < V7.2.8.5 | V7.2.8.5 |
| netgear | rbr860 | < V7.2.8.5 | V7.2.8.5 |
| netgear | rbre950 | < V7.2.8.5 | V7.2.8.5 |
| netgear | rbre960 | < V7.2.8.5 | V7.2.8.5 |
| netgear | rbs750 | < V7.2.8.5 | V7.2.8.5 |
| netgear | rbs840 | < V7.2.8.5 | V7.2.8.5 |
| netgear | rbs850 | < V7.2.8.5 | V7.2.8.5 |
| netgear | rbs860 | < V7.2.8.5 | V7.2.8.5 |
| netgear | rbse950 | < V7.2.8.5 | V7.2.8.5 |
| netgear | rbse960 | < V7.2.8.5 | V7.2.8.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Netgear RBSE960 prior 12.1.2.1 stack-based overflow
vuldb·2026-06-21·CVSS 4.3
CVE-2026-0413 [MEDIUM] Netgear RBSE960 prior 12.1.2.1 stack-based overflow
A vulnerability categorized as critical has been discovered in Netgear RBE37X, RBE77X, RBR750, RBR840, RBR850, RBR860, RBRE950, RBRE960, RBS750, RBS840, RBS850, RBS860, RBSE950 and RBSE960. This vulnerability affects unknown code. Executing a manipulation can lead to stack-based buffer overflow.
This vulnerability is registered as CVE-2026-0413. The attack requires access to the local network. No exploit is available.
It is advisable to upgrade the affected component.
GHSA
Insufficient input validation of buffers vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router softw
ghsa_unreviewed·2026-06-09
CVE-2026-0413 [MEDIUM] CWE-121 Insufficient input validation of buffers vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router softw
Insufficient input validation of buffers vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and functionality.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://kb.netgear.com/000070811/June-2026-NETGEAR-Security-Advisoryhttps://www.netgear.com/support/product/rbe372/https://www.netgear.com/support/product/rbe770/https://www.netgear.com/support/product/rbr750/https://www.netgear.com/support/product/rbr840/https://www.netgear.com/support/product/rbr850/https://www.netgear.com/support/product/rbr860/https://www.netgear.com/support/product/rbre950/https://www.netgear.com/support/product/rbre960/https://www.netgear.com/support/product/rbs750/https://www.netgear.com/support/product/rbs840/https://www.netgear.com/support/product/rbs850/https://www.netgear.com/support/product/rbs860/https://www.netgear.com/support/product/rbse950/https://www.netgear.com/support/product/rbse960/
2026-06-09
Published